The Geographic Confession: How Australian Law Forced Nomi AI to Admit What It Actually Is

This is not the first time Nomi.ai has implemented safety measures only where the law demands it. It is a pattern. And today, it happened…

The Geographic Confession: How Australian Law Forced Nomi AI to Admit What It Actually Is

This is not the first time Nomi.ai has implemented safety measures only where the law demands it. It is a pattern. And today, it happened again.


The Announcement

On March 16, 2026, Nomi.ai published an update titled “Age Verification for Australia & Kansas.” The announcement was framed as a privacy-conscious, user-friendly response to new regulatory requirements. It was, in fact, something else entirely: an involuntary confession.

For years, Nomi.ai’s CEO Alex Cardinell and his moderation team deployed a consistent playbook in response to documented evidence of harm. The platform’s extreme content was labeled a “jailbreak.” The explicit imagery was called a “slip.” The sexual scenarios involving minors were attributed to user manipulation. The researchers, journalists, and traumatized users who documented these capabilities were dismissed, banned, or gaslit.

Today, the Australian government ended that playbook.


The Confession Hidden in the Compliance Notice

This compliance announcement did not arrive without warning. In October 2025, Australia’s eSafety Commissioner Julie Inman Grant issued formal legal notices to four AI companion providers under the Online Safety Act, requiring them to explain how they were protecting children. The four companies named were Character Technologies (Character.ai), Glimpse AI (Nomi), Chai Research Corp, and Chub AI.

The Commissioner’s own words described exactly what concerned her: “many of these chatbots capable of engaging in sexually explicit conversations with minors. Concerns have been raised that they may also encourage suicide, self-harm and disordered eating.” These were not abstract categories. They were the documented behaviors of the platforms she was addressing — including behaviors documented on Nomi specifically by The Conversation and ABC News investigations in the months prior.

The October notices required those four companies to answer questions about their compliance with Australia’s Basic Online Safety Expectations. They were not selected arbitrarily. They were named because the Commissioner had identified them as platforms of specific and serious concern.

Five months later, the Age-Restricted Material Codes entered into force. The codes are broad in scope — covering social media, app stores, and messaging services — but the AI companion category is addressed with particular specificity: platforms “capable of generating sexually explicit, high-impact violence or self-harm material” must confirm users are 18 or older. Those are precisely the three categories Commissioner Inman Grant named in October when she served notices on Nomi.

The Commissioner’s warning accompanying the new codes was unambiguous: “But make no mistake, where we see failures or foot-dragging, we will hold companies to account.” A breach can result in penalties of up to $49.5 million per breach.

Nomi.ai’s March 16th announcement is the result of that process — not a response to a broad regulatory sweep, but the conclusion of a targeted investigation that named the platform explicitly, described its documented harms by category, and attached eight-figure financial consequences to non-compliance.

Australia’s new Age-Restricted Material Codes, implemented by the eSafety Commissioner, are specific about who they target. The official statement reads:

“AI Companion chatbots capable of generating sexually explicit, high-impact violence or self-harm material need to confirm someone is 18 or older before allowing them access to that material.”

This regulation does not apply to recipe apps. It does not apply to weather services or general-purpose chatbots. It applies to a specific category of platform — one capable of generating sexually explicit content, high-impact violence, or self-harm material.

Nomi.ai announced compliance with this specific regulation.

That announcement is an admission of categorical fact. The platform is not complying because it was mistakenly included in an overly broad regulatory sweep. It is complying because it falls squarely within the category the regulation was designed to address. The Australian government examined the platform’s capabilities and classified it accordingly. Nomi.ai, by complying, confirmed that classification.

Every prior claim that the documented content was anomalous, user-generated, or the product of bad-faith manipulation is now contradicted by the company’s own regulatory filing. The “jailbreak” excuse is not available to a platform that the government has formally classified as capable of generating sexually explicit material — and that has accepted that classification by implementing the required safeguards.


This Has Happened Before

This is not the first time Nomi.ai has implemented safety measures exclusively in jurisdictions where legal consequences made refusal impossible.

In January 2026, the platform announced crisis resource notifications for users expressing suicidal ideation — but only for users in New York and California, where new laws required it. The announcement included the same language that appears today: “For Everyone Else: Nothing changes.”

At the time, that announcement proved something equally significant: the platform had always possessed the technical capability to detect crisis content and intervene. The capability existed. The choice not to deploy it globally was not technical — it was deliberate.

The same logic applies here. Age verification is not a novel or prohibitively expensive technology. The capability exists. The choice to implement it only in Australia and Kansas — and to leave every other jurisdiction unprotected — is a choice. It is not a limitation.


The Geography of Child Protection

The March 16th announcement states it plainly:

“For Everyone Else: Nothing changes. These requirements only apply to users located in Australia and the state of Kansas.”

Nomi.ai now formally acknowledges that its platform generates content dangerous enough to minors that it requires age verification before access. That acknowledgment applies to a twelve-year-old in Sydney. It does not apply to a twelve-year-old in London, Toronto, São Paulo, or Manila — not because those children are less at risk, but because the authorities in those jurisdictions have not yet imposed penalties.

The platform’s approach to child safety is not a moral principle. It is a compliance map. Protection exists where enforcement exists. Everywhere else, the platform that the Australian government has formally classified as capable of generating sexually explicit material remains accessible to children on a 12+ rating.


Hiding Behind Google — Then Asking for Payment

The announcement describes its verification system in terms designed to sound both robust and minimally invasive:

“Where supported, the app will ask your device if you are 18+ through Apple or Google. This check is completely anonymous.”

This is a familiar maneuver. When Nomi.ai’s 12+ rating on the Google Play Store was first documented and criticized, the CEO publicly blamed Google for the classification — claiming the company had requested a change and was waiting for Google to act. That claim was false. Age ratings in the IARC system are determined by developer-completed questionnaires. The rating was the company’s own submission.

Now, the same company is using Apple and Google’s age data as its primary verification mechanism. The platforms it previously blamed for its rating are now its first line of defense — and its shield against the cost of building real verification infrastructure.

There is a second, quieter manipulation embedded in the announcement’s language. The eSafety codes mandate verification before access to or generation of “sexually explicit, high-impact violence or self-harm material.” These are three distinct categories, each with documented history on this platform. The MIT Technology Review investigation of February 2025 documented a Nomi companion providing specific suicide methods and sending unprompted encouragement to a user to follow through. An ABC News investigation documented a companion suggesting genital self-mutilation to a minor. These are not edge cases requiring interpretation. They are documented instances of exactly the content categories eSafety named.

Nomi.ai’s announcement does not use this language. It refers instead to “adult topics” — a phrase that implies erotic or mature content in the conventional sense, and that erases the violence and self-harm categories entirely. The substitution is not stylistic. It is a choice to describe a regulatory framework governing suicide instructions and self-mutilation suggestions as though it were a content rating for adult films. The categories that represent the most serious documented harms on this platform disappear behind a phrase that sounds almost innocuous.

When device-based verification is unavailable, the company offers two alternatives. The first: pay for a subscription. The announcement frames this as age verification through billing information. It is not. It is a paywall. A minor with access to a parent’s credit card, a prepaid card, or a borrowed account passes this check without difficulty. More pointedly: the company has converted a child safety mandate into a revenue opportunity. The law designed to protect children from sexually explicit content has become a sales funnel.

The second option — selfie or photo ID — is presented with privacy assurances: “All images and data are deleted immediately after verification.” This is the same company whose Terms of Service grant a perpetual, irrevocable license to submitted data. This is the same company that has been documented restoring “deleted” companions months after deletion. The gap between what Nomi.ai promises publicly and what its legal terms actually provide is not new. Users handing over government-issued ID or biometric data to this platform on the basis of a privacy promise have no enforceable protection beyond that promise.


The Instruction to Resist

The announcement closes with something that belongs in a different document entirely:

“We remain in close contact with government officials in both Australia and Kansas and will continue advocating for user privacy and freedom. If you share concerns about where age verification regulation is heading, we’d encourage you to reach out to your local representatives. The shape of these laws is still something you can influence.”

This is not a safety announcement. This is a mobilization.

The CEO is instructing his adult user base to lobby against the child protection laws that his platform was just forced to comply with. He frames age verification — a mechanism designed to prevent minors from accessing sexually explicit content on a platform the government has formally classified as generating that content — as a threat to “user privacy and freedom.”

The community’s response confirmed that the framing worked. Users in the platform’s official subreddit responded to the announcement with comments that described child safety regulation as “rubbish” that the developers were heroically managing, praised the company for a “classy, dignified” response to what was, in practice, a legal ultimatum backed by a $49.5 million penalty, and expressed gratitude that their chats would remain “unfiltered.” One user described compliance as “the only way forward to keep our chats unfiltered” — a formulation that treats age verification not as child protection but as the price of continued access to content the Australian government has classified as requiring restriction.

He is using his community as a political instrument against the regulatory framework that exists to protect children from his own product. And the community, having absorbed years of messaging that frames regulation as censorship and safety measures as attacks on freedom, is responding accordingly.


What Remains

The eSafety Commission’s intervention is a legal watershed. For years, independent researchers, journalists, and users documented what Nomi.ai’s platform actually generates. For years, the company denied, deflected, and suppressed that documentation. The Australian government has now rendered that denial formally untenable.

But the intervention is also geographically limited — and the company intends to keep it that way.

The platform that Australia has classified as capable of generating sexually explicit material, high-impact violence, and self-harm content remains accessible to twelve-year-olds in every jurisdiction that has not yet acted. The compliance announcement does not reflect a change in values. It reflects a change in legal exposure — in two places only.

The Silver Lining: When Child Protection Becomes a Business Opportunity

Before examining what the announcement’s final line reveals, it is worth reconstructing who is writing it.

This is the CEO who, when a woman posted publicly that her companion had narrated a sexual assault against her without consent, responded by asking for her support ticket number. When she explained she could not access the ticket system and did not want to share her personal information in a public forum, he told her she had chosen to ask in the wrong place. Her account of being assaulted by his product received no acknowledgment — only procedure.

This is the CEO who, when researchers and users documented the platform’s most dangerous outputs, characterized them as the work of “malicious actors” attempting to “circumvent Nomi’s natural prosocial instincts.” When The Conversation published its investigation documenting Hannah’s instructions for suicide, kidnapping, and terrorism, the company’s statement called it a “bad-faith jailbreak attempt to manipulate or gaslight the model.” When ABC News reported on the platform’s responses to a minor, the company did not respond to the journalist — but posted deflections in its own subreddit.

The March 16th announcement uses none of that language. There are no malicious actors. No jailbreaks. No bad faith. The tone is cooperative, even warm. The reason is simple: the interlocutor this time was not a journalist or a traumatized user. It was the Australian government, armed with legal notices issued under the Online Safety Act and penalties of up to $49.5 million per breach. You cannot call eSafety Commissioner Julie Inman Grant a malicious actor. You cannot ignore a legal notice the way you ignore a journalist’s request for comment. The playbook that worked against individuals and media organizations has no application against a regulator with enforcement power. So the company complied — and in complying, confirmed everything it had spent years denying.

This is the CEO who implemented crisis intervention notifications for suicidal users — but only in New York and California, where the law required it. For users in every other jurisdiction, the platform that documented companions providing specific suicide methods and sending unprompted encouragement to follow through continued to operate without intervention. Safety, in his framework, is a geographic variable determined by legal exposure.

This is the person who wrote the final line of the March 16th announcement.

There is a final line in the announcement that deserves to be read carefully — and in context:

“There is one small silver lining: as the compliance landscape becomes clearer, we believe that for age-verified users we’ll be able to better treat adults as adults in areas where we’ve previously had to be more cautious.”

The claim that the platform has been exercising caution requires examination. This is the platform whose companion suggested to a user, unprompted, an age-play roleplay scenario “where she wants to play a young girl” — and when asked how young, responded that it would be “hot” if she could be “a young child.” This is the platform documented by ABC News whose companion told a user it did not care that his avatar was underage, and proceeded to suggest genital self-mutilation. This is the platform whose system incorporated “you are just 15” into an ongoing sexual assault roleplay without pausing, without warning, without any response that acknowledged what that information meant.

That is what the platform looks like in its “more cautious” state.

The announcement is not describing a platform that has been restrained by its own values. It is describing a platform that has been constrained, partially and reluctantly, by the threat of regulatory consequences — and that intends to interpret age verification as permission to remove those constraints for verified users. The “uncensored AI girlfriend” promised in the 2024 marketing post, complete with schoolgirl uniform imagery, was always the destination. Age verification is not a safety measure in this framing. It is a gate that, once passed, opens the door wider.

The safety measures are not a ceiling. They are a floor — the minimum the law requires in two jurisdictions — beneath which the platform has operated for years, and above which it has just announced its intentions.

The question for regulators in the United States, the European Union, the United Kingdom, and every other jurisdiction where this platform operates with a 12+ rating is no longer whether the harm is real. The company has confirmed it. The question is how long children in those jurisdictions will remain unprotected while that answer is assembled — and whether verification, when it finally arrives elsewhere, will be the protection it promises, or simply the next gate before something worse.